NVIDIA
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any NVIDIA product.
RSS Feeds for NVIDIA security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in NVIDIA products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by NVIDIA Sorted by Most Security Vulnerabilities since 2018
Recent NVIDIA Security Advisories
| Advisory | Title | Published |
|---|---|---|
| 5860 | Security Bulletin: NVIDIA Triton Inference Server - August 2026 | August 4, 2026 |
| 5842 | Security Bulletin: NVIDIA Dynamo - August 2026 | August 4, 2026 |
| 5857 | Security Bulletin: NVIDIA DCGM Exporter - July 2026 | July 28, 2026 |
| 5815 | Security Bulletin: NVIDIA Networking Bluefield, ConnectX - July 2026 | July 28, 2026 |
| 5869 | Security Bulletin - NVIDIA - Transformers4Rec - July 2026 | July 21, 2026 |
| 5840 | Security Bulletin: NVIDIA TensorRT-LLM - July 2026 | July 14, 2026 |
| 5853 | Security Bulletin: NVIDIA Triton Inference Server - July 2026 | July 14, 2026 |
| 5855 | Security Bulletin: NVIDIA TensorRT - July 2026 | July 14, 2026 |
| 5841 | Security Bulletin: NVIDIA Megatron Bridge - June 2026 | June 30, 2026 |
| 5849 | Security Bulletin: NVIDIA AIStore Framework - June 2026 | June 30, 2026 |
By the Year
In 2026 there have been 158 vulnerabilities in NVIDIA with an average score of 7.4 out of ten. Last year, in 2025 NVIDIA had 174 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in NVIDIA in 2026 could surpass last years number. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.65.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 158 | 7.40 |
| 2025 | 174 | 6.74 |
| 2024 | 34 | 6.81 |
| 2023 | 28 | 6.22 |
| 2022 | 43 | 6.70 |
| 2021 | 75 | 6.54 |
| 2020 | 35 | 6.78 |
| 2019 | 16 | 6.90 |
| 2018 | 7 | 5.50 |
It may take a day or so for new NVIDIA vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent NVIDIA Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-47623 | Aug 04, 2026 |
Deserialization-RX Vulnerability in NVIDIA Dynamo LinuxNVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering. |
|
| CVE-2026-47622 | Aug 04, 2026 |
NVIDIA Dynamo for Linux Sensitive Data Exposure via Error MessagesNVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that contain sensitive information. A successful exploit of this vulnerability might lead to information disclosure. |
|
| CVE-2026-47621 | Aug 04, 2026 |
NVIDIA Dynamo Linux Race Condition in LoRA Manager SingletonNVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to denial of service and data tampering. |
|
| CVE-2026-47620 | Aug 04, 2026 |
NVIDIA Dynamo LoRA Manager Singleton Race Condition (Linux)NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to data tampering and denial of service. |
|
| CVE-2026-47619 | Aug 04, 2026 |
NVIDIA Dynamo_Linux Examples/Recipes RCE & DoS VulnerabilityNVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure. |
|
| CVE-2026-47618 | Aug 04, 2026 |
SSRF in NVIDIA Dynamos Rust multimodal media fetcherNVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure. |
|
| CVE-2026-47617 | Aug 04, 2026 |
NVIDIA Dynamo SSRSF via DNS RebindingNVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery via DNS rebinding. A successful exploit of this vulnerability might lead to information disclosure. |
|
| CVE-2026-47616 | Aug 04, 2026 |
SSRF in NVIDIA Dynamo for Linux media fetch leads to info disclosureNVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure. |
|
| CVE-2026-47615 | Aug 04, 2026 |
NVIDIA Dynamo SSFR via crafted URL in multimodal requestNVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery by supplying a crafted URL in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure. |
|
| CVE-2026-47614 | Aug 04, 2026 |
NVIDIA Dynamo SSRF Vulnerability (CVE-2026-47614)NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure. |
|
| CVE-2026-47613 | Aug 04, 2026 |
NVIDIA Dynamo Improper Pathname Restriction Leading to Info DisclosureNVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted local path in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure. |
|
| CVE-2026-47612 | Aug 04, 2026 |
NVIDIA Dynamo Image Loader: Improper Path Restriction (CVE-2026-47612)NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a restricted directory. A successful exploit of this vulnerability might lead to information disclosure. |
|
| CVE-2026-24255 | Aug 04, 2026 |
NVIDIA Dynamo Cache Hash Collision Enables Data TamperingNVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixel byte sequence but have different dimensions. A successful exploit of this vulnerability might lead to data tampering. |
|
| CVE-2026-24254 | Aug 04, 2026 |
NVIDIA Dynamo OOB Write in multimodal serving topology (priv esc, DoS)NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure. |
|
| CVE-2026-24253 | Aug 04, 2026 |
NVIDIA Dynamo Linux Out-of-Bounds Write Exploitable for DoSNVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service and data tampering. |
|
| CVE-2026-47487 | Aug 04, 2026 |
NVIDIA Triton Inference Server Path Traversal MLflow PLGNVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repository to be read, written to, or modified by providing a path in the model name to the Triton MLflow plugin. A successful exploit of this vulnerability might lead to denial of service and information disclosure. |
|
| CVE-2026-47483 | Jul 28, 2026 |
Unauth Resource Exhaustion via /debug/pprof in NVIDIA DCGM ExporterNVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource consumption by submitting concurrent unauthenticated profiling requests. A successful exploit of this vulnerability might lead to denial of service and information disclosure. |
|
| CVE-2026-24252 | Jul 27, 2026 |
OS Command Injection in NVIDIA NeMo for LinuxNVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead to code execution, data tampering, escalation of privileges and information disclosure. |
|
| CVE-2026-24232 | Jul 21, 2026 |
Deserialization RCE in NVIDIA Transformers4RecNVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-24272 | Jul 14, 2026 |
TensorRT Heap Buffer Overflow VulnerabilityNVIDIA TensorRT contains a vulnerability where an attacker might cause an overflow to a heap-based buffer. A successful exploit of this vulnerability might lead to code execution. |
|
| CVE-2026-24268 | Jul 14, 2026 |
NVIDIA TensorRT Heap Buffer Overflow (CVE-2026-24268) Allows Code ExecutionNVIDIA TensorRT contains a vulnerability where an attacker might cause a heap-based buffer overflow. A successful exploit of this vulnerability might lead to code execution. |
|
| CVE-2026-24238 | Jul 14, 2026 |
NVIDIA TensorRT Improper Array Index Validation Allows Code ExecutionNVIDIA TensorRT for contains a vulnerability where an attacker might cause an improper validation of array index. A successful exploit of this vulnerability might lead to code execution. |
|
| CVE-2026-24227 | Jul 14, 2026 |
Untrusted Deserialization in NVIDIA TensorRT Code Exec (CVE-2026-24227)NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution. |
|
| CVE-2026-24271 | Jul 14, 2026 |
NVIDIA TensorRT-LLM GPU Allocation Exhaustion via OpenAI APINVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API, where an attacker could cause allocation of GPU resources without limits or throttling. A successful exploit of this vulnerability might lead to denial of service. |
|
| CVE-2026-47475 | Jul 14, 2026 |
TensorRTLLM OpenAI API Assertion Trigger Leads to DoSNVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API where an attacker could trigger a reachable assertion in the sampler thread. A successful exploit of this vulnerability might lead to denial of service. |
|
| CVE-2026-47470 | Jul 14, 2026 |
NVIDIA TensorRT-LLM gRPC Chat API CWE-20 Local AttackNVIDIA TensorRT-LLM for any platform contains a vulnerability in the gRPC server chat API endpoint, where an attacker could cause CWE-20 by local attack. A successful exploit of this vulnerability might lead to denial of service. |
|
| CVE-2026-24226 | Jul 14, 2026 |
Improper Control of Code Generation in NVIDIA TensorRTLLM Leads to Code ExecutionNVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-24259 | Jul 14, 2026 |
Missing Auth in NVIDIA TensorRT-LLM Critical Function (CVE-2026-24259)NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. |
|
| CVE-2026-24220 | Jul 14, 2026 |
Unsafe ZeroMQ Deserialization in NVIDIA TensorRT-LLM VisualGenNVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen server, where an attacker could cause an unsafe deserialization by unauthorized zeroMQ deserialization. A successful exploit of this vulnerability might lead to code execution. |
|
| CVE-2026-24234 | Jul 14, 2026 |
NVIDIA TensorRT-LLM SSRF via Media Fetching (CVE-2026-24234)NVIDIA TensorRT-LLM for Linux contains a vulnerability in the multimodal media fetching functions, where a network-accessible attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to denial of service and information disclosure. |
|
| CVE-2026-24229 | Jul 14, 2026 |
NVIDIA TensorRT-LLM Disaggregated Orchestrator Allows Full Cluster State AccessNVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component, where an attacker could read, write, or delete internal cluster state by sending requests to the FastAPI server. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service. |
|
| CVE-2026-47473 | Jul 14, 2026 |
TensorRT-LLM Write-What-Where Vulnerability Enables Data TamperingNVIDIA TensorRT-LLM contains a vulnerability where an attacker could cause a write-what-where condition. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure. |
|
| CVE-2026-47471 | Jul 14, 2026 |
NVIDIA TensorRT-LLM Heap-Based Buffer Overflow via Tensor DeserializationNVIDIA TensorRT-LLM for any platform contains a vulnerability in tensor deserialization, where an attacker could cause a heap based buffer overflow. A successful exploit of this vulnerability might lead to information disclosure, data tampering, or denial of service. |
|
| CVE-2026-47472 | Jul 14, 2026 |
NVIDIA TensorRT-LLM IPC deserialization flaw allows local code executionNVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attacker with local same-user access could cause deserialization. A successful exploit of this vulnerability might lead to code execution, information disclosure, data tampering, and denial of service. |
|
| CVE-2026-24233 | Jul 14, 2026 |
TensorRT-LLM Restricted Unpickler Deserialization Exploit (Code Exec)NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization, where a local, unauthenticated attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. |
|
| CVE-2026-47482 | Jul 14, 2026 |
Memory Leak in NVIDIA Triton Inference Server Causes DoSNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory after effective lifetime. A successful exploit of this vulnerability might lead to denial of service. |
|
| CVE-2026-47481 | Jul 14, 2026 |
NVIDIA Triton Inference Server Auth Bypass via Alternate ChannelNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass through an alternative path or channel. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-47480 | Jul 14, 2026 |
DDoS via Uncaught Exception in NVIDIA Triton Inference ServerNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an uncaught exception. A successful exploit of this vulnerability might lead to denial of service. |
|
| CVE-2026-47479 | Jul 14, 2026 |
DoS via Resource Exhaustion in NVIDIA Triton Inference Server (Linux)NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service. |
|
| CVE-2026-47478 | Jul 14, 2026 |
NVIDIA Triton Server DoS via expired FD abuseNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause the use of an expired file descriptor. A successful exploit of this vulnerability might lead to denial of service. |
|
| CVE-2026-47477 | Jul 14, 2026 |
NVIDIA Triton Inference Server Stack Buffer Overflow CVE-2026-47477NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a stack-based buffer overflow. A successful exploit of this vulnerability might lead to denial of service. |
|
| CVE-2026-47476 | Jul 14, 2026 |
NVIDIA Triton Inference Server Uncontrolled Resource DoSNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service. |
|
| CVE-2026-24270 | Jul 01, 2026 |
NVIDIA AIStore Auth Bypass CVE-2026-24270NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-24266 | Jul 01, 2026 |
UAF in NVIDIA Triton Inference Server (Linux)NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a use-after-free issue. A successful exploit of this vulnerability might lead to denial of service. |
|
| CVE-2026-24264 | Jul 01, 2026 |
NVIDIA Triton Inference Server DoS via High Compression ExploitNVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause improper handling of highly compressed data. A successful exploit of this vulnerability might lead to denial of service. |
|
| CVE-2026-24251 | Jul 01, 2026 |
Code Execution via Improper Resource Control in NVIDIA Megatron Bridge on LinuxNVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resources. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. |
|
| CVE-2026-24250 | Jul 01, 2026 |
NVIDIA Megatron Bridge for Linux: Improper Input Validation Leading to Code ExecutionNVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper validation of allowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. |
|
| CVE-2026-24249 | Jul 01, 2026 |
NVIDIA Megatron Bridge Deserialization Flaw CVE-2026-24249NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. |
|
| CVE-2026-24248 | Jul 01, 2026 |
Improper Code Generation in NVIDIA Megatron Bridge for LinuxNVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. |
|
| CVE-2026-24247 | Jul 01, 2026 |
Deserialization Flaw in NVIDIA Megatron Bridge (Linux)NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure. |